1

Grc Risk Analyst Jobs in Pennsylvania (NOW HIRING)

The Global GRC Senior Analyst will report directly to the Global Cybersecurity Governance, Risk and Compliance Manager. This role involves collaborating with cross-functional teams to design ...

The Analyst independently leads risk assessments and partners closely with IT, OT, audit, andsenior ... Experience using Governance, Risk, and Compliance (GRC) tools and risk reporting dashboards.

Cybersecurity Senior GRC Analyst

Denver, PA · On-site

$96K - $123K/yr

Job Summary The Governance Risk & Compliance (GRC) Cybersecurity Senior Analyst plays a critical role in ensuring that UGI Utilities Inc. operates within its regulatory, legal, and compliance ...

Cybersecurity Senior GRC Analyst

Denver, PA

$96K - $123K/yr

Job Summary The Governance Risk & Compliance (GRC) Cybersecurity Senior Analyst plays a critical role in ensuring that UGI Utilities Inc. operates within its regulatory, legal, and compliance ...

Senior GRC Analyst

Pittsburgh, PA · On-site

$114K - $163K/yr

Senior GRC Analyst Department: Compliance & Fraud Employment Type: Full Time Location: Pittsburgh ... Execute third-party risk assessments across our vendor portfolio, including security questionnaire ...

As a GRC Engineer here at Chubb, you will apply engineering, automation, and data analytics ... In this role, you will connect data, controls, and risk signals to drive deeper risk analysis ...

As a GRC Engineer here at Chubb, you will apply engineering, automation, and data analytics ... In this role, you will connect data, controls, and risk signals to drive deeper risk analysis ...

IRC Analyst

Mount Joy, PA · Hybrid

$70K - $110K/yr

Prepare risk assessments and generate risk and control matrices (RACM); update GRC systems with ... Analyze transactions, documentation, and reporting to assess adequacy and process effectiveness.

IRC Analyst

Reedsville, PA · Hybrid

$70K - $110K/yr

Prepare risk assessments and generate risk and control matrices (RACM); update GRC systems with ... Analyze transactions, documentation, and reporting to assess adequacy and process effectiveness.

IRC Analyst

Mount Joy, PA · On-site

$70K - $110K/yr

Prepare risk assessments and generate risk and control matrices (RACM); update GRC systems with ... Analyze transactions, documentation, and reporting to assess adequacy and process effectiveness.

IRC Analyst

Reedsville, PA · On-site

$70K - $110K/yr

Prepare risk assessments and generate risk and control matrices (RACM); update GRC systems with ... Analyze transactions, documentation, and reporting to assess adequacy and process effectiveness.

next page

Showing results 1-20

Grc Risk Analyst information

What is the difference between Grc Risk Analyst vs Compliance Analyst?

AspectGrc Risk AnalystCompliance Analyst
CertificationsISO 31000, FRM, CRISCISO 19600, CCEP, CISA
Work EnvironmentRisk management teams, corporate officesRegulatory departments, corporate offices
Industry UsageFinance, banking, insurance, corporate riskFinancial services, healthcare, manufacturing
Job FocusIdentifying, assessing, and mitigating risks across enterpriseEnsuring compliance with laws and regulations

While both roles involve regulatory and risk considerations, a Grc Risk Analyst focuses on enterprise-wide risk management strategies, whereas a Compliance Analyst concentrates on adherence to specific laws and regulations. Both roles require similar certifications and often work in overlapping industries, but their core responsibilities differ in scope and focus.

What is a GRC Risk Analyst?

GRC Risk Analysts are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization. They assess and manage risks related to business operations, ensure compliance with relevant laws and regulations, and help implement policies and controls to mitigate potential threats. These analysts work closely with management to identify vulnerabilities, develop risk management strategies, and monitor the effectiveness of compliance programs. Their goal is to protect the organization from financial, legal, and reputational harm while supporting business objectives.

What are the key skills and qualifications needed to thrive as a GRC Risk Analyst?

To thrive as a GRC (Governance, Risk, and Compliance) Risk Analyst, you need a solid understanding of risk management principles, regulatory requirements, and compliance frameworks, often supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (such as RSA Archer or MetricStream), risk assessment methodologies, and certifications like CRISC or CISA is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and convey findings to stakeholders. These skills are critical for ensuring organizational compliance, minimizing risk exposure, and supporting informed decision-making.

What are some common challenges a GRC Risk Analyst might face when implementing new risk management frameworks within an organization?

A GRC Risk Analyst often encounters challenges such as resistance to change from stakeholders, integrating new frameworks with existing processes, and ensuring consistent understanding across departments. Aligning risk management practices with organizational goals while adhering to regulatory requirements can also be complex. Success in this role requires strong communication skills, adaptability, and the ability to educate and collaborate with team members from diverse backgrounds.

What cities in Pennsylvania are hiring for Grc Risk Analyst jobs?

Cities in Pennsylvania with the most Grc Risk Analyst job openings:

Infographic showing various Grc Risk Analyst job openings in Pennsylvania as of August 2026, with employment types broken down into 1% As Needed, 82% Full Time, 14% Part Time, 2% Contract, and 1% Nights. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution.

Global Sr GRC Analyst

UGI

King Of Prussia, PA • On-site

Full-time

Re-posted 23 days ago


Job description

Requisition Number: 29563 

When you work for AmeriGas, you become a part of something BIG! Founded in 1959, AmeriGas is the nation's premier propane company, serving over 1.5 million residential, commercial, industrial and motor fuel propane customers. Together, over 6,500 dedicated professionals will deliver over 1 billion gallons of propane from 1,800+ distribution points across the United States.

Job Summary:

The Global Cybersecurity Senior GRC Analyst plays a critical role in ensuring that the organization operates within its regulatory, legal, and compliance obligations while managing risk effectively. The Global GRC Senior Analyst will report directly to the Global Cybersecurity Governance, Risk and Compliance Manager.  This role involves collaborating with cross-functional teams to design, implement, and maintain governance, risk, and compliance processes. The ideal candidate is detail-oriented, analytical, and experienced in regulatory compliance, risk management frameworks, and governance best practices and must develop and apply continuous improvement strategies in all aspects of the job function.

Key Responsibilities:

Governance:

             Develop and maintain corporate policies, procedures, and frameworks to align with industry best practices (e.g., NIST CSF, SOX, PCI, etc.).

  • Assist with the development and maintenance of GRC process and procedure documentation.

             Ensure IT functions are in compliance with best practices and company policies and standards through assessments (i.e. peer reviews, audits, etc.)

  • Track key risk indicators and security metrics

Risk Management:

             Assist with conducting gap assessments to identify threats, vulnerabilities, and potential impacts on the organization.

             Develop and maintain the risk register, ensuring risks are documented, prioritized, and mitigated.

             Perform third-party/vendor risk assessments to evaluate potential risks associated with external partnerships and perform on-going monitoring to assess risk of engagement.

  • Maintain centralize documentation, continuous monitoring for vendors, formal escalation protocols for non-compliance to ensure alignment with enterprise risk tolerance.
  • Document risk acceptance decisions and compensating controls
  • Develop and maintain templates for consistent risk documentation
  • Assist in evaluating cybersecurity risk on incoming projects.
  • Assist and support team in performing cybersecurity due diligence on merger/acquisition targets.

Compliance:

             Ensure compliance with regulatory requirements (e.g., GDPR, HIPAA, SOX, PCI-DSS) and industry standards through monitoring and reporting metrics, security exceptions and using other methods to monitor compliance

           Drive compliance by maintaining the compliance framework  to ensure policies and standards align to regulatory requirements, laws and best practices.

Stakeholder Engagement

  • Collaborate with business units to understand critical processes
  • Educate stakeholders on risk management concepts and frameworks
  • Partner with technical teams to validate remediation plans
  • Present risk findings to appropriate governance committees
  • Coordinate and collaborate with stakeholders to establish and track metrics for governance programs.

                 Collaborate with stakeholders to monitor regulatory and industry developments to ensure  

                  compliance with changes.

  • Coordinate and collaborate with stakeholders to track outcomes and metrics for all third-party breaches.
  • Advise stakeholders on compliance requirements and incorporate new metrics into governance life cycle process, including new tools as they are onboarded.
  • Coordinate the review of Policies and Standards through collaborating with stakeholders.

Collaboration and Reporting:

             Partner with IT, Legal, HR, and other departments to ensure alignment on risk and compliance efforts.

             Create and deliver regular risk and compliance metrics for senior leadership and boards.

             Serve as a subject matter expert (SME) for GRC-related queries and initiatives.

Qualifications:

Education and Experience:

             Bachelor's degree in Information Security, Risk Management, Computer Science, or related field, required.

             4+ years of experience in GRC, risk management, or compliance roles.

Skills and Competencies:

             Strong understanding of GRC tools and platforms (e.g., RSA Archer, ServiceNow GRC).

             Familiarity with risk management frameworks (e.g., COBIT, FAIR) and compliance standards.

             Exceptional analytical, problem-solving, and organizational skills.

             Strong written and verbal communication skills, with the ability to interact effectively with stakeholders at all levels.

             Certifications such as CRISC, CISM, CISA or CISSP highly preferred.

Key Attributes:

                            Attention to detail and ability to manage multiple priorities.

                            Proactive mindset with a focus on continuous improvement.

                            Collaborative team player who can influence without authority.

AmeriGas Propane, Inc. is an Equal Opportunity Employer. The Company does not discriminate on the basis of race, color, sex, national origin, disability, age, gender identity, sexual orientation, veteran status, or any other legally protected class in its practices.

AmeriGas is a Drug Free Workplace. Candidates must be willing to submit to a pre-employment drug screen and a criminal background check. Successful applicants shall be required to pass a pre-employment drug screen as a condition of employment, and if hired, shall be subject to substance abuse testing in accordance with AmeriGas policies. As a federal contractor that engages in safety-sensitive work, AmeriGas cannot permit employees in certain positions to use medical marijuana, even if prescribed by an authorized physician.  Similarly, applicants for such positions who are actively using medical marijuana may be denied hire on that basis.


UGI logo

About UGI

Sourced by ZipRecruiter

UGI Corporation, headquartered in King of Prussia, PA, US, is a diversified utility service company engaged in the distribution and marketing of energy products and services on an international scale. Founded in 1882, the corporation operates through its various subsidiaries in the domestic and international markets. Its repertoire of products and services includes natural gas, liquid fuels, and electricity. The company has fundamentally positioned itself as a leader in the energy industry with a commitment to safety, reliability, and exceptional service. UGI's mission revolves around leading the way in delivering reliable, safe, and efficient energy solutions for customers.

Industry

Utilities

Company size

10,000+ Employees

Headquarters location

King of Prussia, PA, US

Year founded

1882

Social media